This message was deleted.
# citrix-netscaler
s
This message was deleted.
d
Dennis, thanks, this won't help an end user though.. I'm trying to find a way to make it clear to an end user it's not a password issue... It's really not a huge deal, cuz they'll end up calling an admin anyway.. but i could see this alert confusing the help desk
m
Maybe enhanced authentication Feedback helps
j
I understand your question, but you do need to take into account the added security risks when more detailed information is available for failed authentication. If an attacker gets the message that the user account does not belong to the required security group, they know the credentials are correct. Result is they start looking for other ways to get in, as they now have a valid user account. The best way to get around this is to not have a dedicated url for authentication, like aaa.domain.com or auth.domain.com if possible. If you use the application url like app.domain.com for authentication, the service request for help should know what to check when a call comes in as they only have to ask which url was used.
👍 1
d
This is a great point and I thank you for bringing it up
👍 1